
CS OCSP Services
160
Red Hat Certificate System Administrator’s Guide • September 2005
How Certificate Manager’s OCSP-Service Feature Works
The Certificate Manager has a built-in OCSP-service feature, which when configured, can
be used by OCSP-compliant clients to directly query the Certificate Manager about the
revocation status of the certificate being validated. The OCSP service is installed and
configured by default, and is one of the options during install. Unless you deselected this
option, the service was installed and configured.
Clients can query the OCSP through the non-SSL end-entity port of the Certificate
Manager. When queried for the revocation status of a certificate, the Certificate Manager
looks up its internal database for the certificate, checks its status, and accordingly responds
to the client. Since the Certificate Manager has real-time status of all certificates it has
issued, this method of revocation checking is most accurate.
Since the internal OCSP service checks the status of certificates stored in the Certificate
Manager’s internal database, you do not need to set up publishing to use this service. The
certificates are stored, and revoked certificates are marked revoked in the internal database
of the Certificate Manager by default.
For step-by-step instructions to set up an OCSP-compliant PKI setup using the Certificate
Manager, see “Setting Up a Certificate Manager with OCSP Service” on page 161.
How the Online Certificate Status Manager Works
In addition to the built-in OCSP service feature, the Certificate Manager can also publish
CRLs to an OCSP-compliant online validation authority. If you install the CS OCSP
responder, Online Certificate Status Manager, you can configure one or more Certificate
Managers to publish their CRLs to the Online Certificate Status Manager. The Online
Certificate Status Manager stores each Certificate Manager’s CRL in its internal database
and uses the appropriate CRL to verify the revocation status of a certificate when queried by
an OCSP-compliant client. (Note the difference between the Online Certificate Status
Manager and the internal OCSP service. The internal OCSP service checks certificate status
by checking the internal database of the Certificate Manager. The Online Certificate Status
Manager checks certificate status by checking CRLs provided by the Certificate Manager
that it stores in its own internal database.)
You can configure the Certificate Manager to generate and publish CRLs whenever a
certificate is revoked and at specified intervals, say every 20 minutes. Because the purpose
of setting up an OCSP responder is to facilitate real-time verification of certificates, you
should configure the Certificate Manager to generate and publish the CRL to the Online
Certificate Status Manager every time a certificate is revoked—configuring the Certificate
Manager to publish CRLs at specific intervals would negate the very purpose for which it’s
being done because the CRL the Online Certificate Status Manager would look up during
verification would always be outdated. It’s important to note that if the CRL is large, the
Certificate Manager could take a considerable amount of time to publish the CRL.
Содержание CERTIFICATE 7.1 ADMINISTRATOR
Страница 1: ...Administrator s Guide Red Hat Certificate System Version7 1 September 2005 ...
Страница 22: ...22 Red Hat Certificate System Administrator s Guide September 2005 ...
Страница 128: ...Cloning a CA 128 Red Hat Certificate System Administrator s Guide September 2005 ...
Страница 230: ...Configuring Key Archival and Recovery Process 230 Red Hat Certificate System Administrator s Guide September 2005 ...
Страница 234: ...Enterprise Security Client 234 Red Hat Certificate System Administrator s Guide September 2005 ...
Страница 368: ...ACL Reference 368 Red Hat Certificate System Administrator s Guide September 2005 ...
Страница 460: ...Constraints Reference 460 Red Hat Certificate System Administrator s Guide September 2005 ...
Страница 592: ...CRL Extension Reference 592 Red Hat Certificate System Administrator s Guide September 2005 ...
Страница 676: ...Cloning the Data Recovery Manager 676 Red Hat Certificate System Administrator s Guide September 2005 ...
Страница 688: ...Security Requirements for the IT Environment 688 Red Hat Certificate System Administrator s Guide September 2005 ...
Страница 720: ...1 3 Organization Security Policies 720 Red Hat Certificate System Administrator s Guide September 2005 ...